CVE-2022-43904Improper Restriction of Excessive Authentication Attempts in IBM Security Guardium

Severity
7.5HIGHNVD
EPSS
0.1%
top 80.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 28

Description

IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/security_guardium11.3, 11.4
NVDibm/security_guardium11.3, 11.4+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f68g-gx28-g956: IBM Security Guardium 112023-08-28
CVEList
IBM Security Guardium information disclosure2023-08-27
CVE-2022-43904 — IBM Security Guardium vulnerability | cvebase